PREAMBLE
This Data Processing Agreement (hereinafter the “DPA”) is entered into between Nereva SA, a company limited by shares under Swiss law, whose registered office is at Rue de Rive 22D, CH-1260 Nyon (Switzerland), entered in the commercial register of the canton of Vaud under business identification number CHE-294.630.698, hereinafter referred to as “Nereva” or the “Processor”, on the one hand, and the Client identified in the order form, hereinafter referred to as the “Client” or the “Controller”, on the other hand. Hereinafter together the “Parties” and individually the “Party”.
Statutory corporate purpose of Nereva SA. In accordance with Article 3 of its articles of association entered in the commercial register of the canton of Vaud, the purpose of Nereva SA is the design, development, publishing, marketing, integration and operation, in Switzerland and abroad, of software and digital solutions for orchestrating and synchronising logistics flows operated by vehicles, in particular flows of materials, waste, machinery, equipment and skips linked to construction, civil engineering, recycling, construction-site transport and related sectors.
The company may in particular provide, in the form of software on demand (Software as a Service) or licences, platforms for planning, executing, documenting, tracing and archiving logistics operations, as well as associated configuration, integration, support, training and consulting services.
The company may acquire, hold, exploit, license and defend any intellectual property right, in particular patents, trademarks, designs, models, copyrights and know-how, directly or indirectly related to its main purpose.
The company may carry out, both in Switzerland and abroad, on its own behalf or on behalf of third parties, all administrative, technical, commercial, financial, movable and immovable transactions directly or indirectly related to its main purpose. It may establish branches and subsidiaries in Switzerland and abroad, acquire holdings in companies pursuing a similar or complementary purpose, and grant loans or guarantees to its subsidiaries and group companies.
The company does not carry out any transport activity and does not act as a commercial intermediary between principals and transport companies. It does not capture the commercial contractual relationship between its users.
Purpose and articulation of this DPA. This DPA constitutes a contractual annex inseparable from the Terms and Conditions of Use (“T&Cs”) and the order form concluded between the Parties. Its purpose is to define the conditions under which Nereva, as processor within the meaning of Article 28 of the GDPR and Article 9 of the FADP, processes personal data on behalf of the Client in the context of the performance of the Services.
TABLE OF CONTENTS
Article 1 — Purpose and scope
Article 2 — Definitions
Article 3 — Qualification of the Parties
Article 4 — Description of the processing
Article 5 — Obligations of Nereva as Processor
Article 6 — Documented instructions of the Controller
Article 7 — Obligations of the Controller
Article 8 — Confidentiality
Article 9 — Security measures
Article 10 — Sub-processing
Article 11 — International data transfers
Article 12 — Assistance to the Controller
Article 13 — Notification of data breaches
Article 14 — Fate of data at the end of the contract
Article 15 — Audit
Article 16 — Liability
Article 17 — Term and termination
Article 18 — Applicable law and jurisdiction
Article 19 — Reference language
Article 20 — Annexes
Annex 1 — Description of the processing
Annex 2 — Technical and organisational security measures
Annex 3 — List of authorised sub-processors
Article 1 — Purpose and scope
This DPA governs the processing by Nereva, as Processor, of the personal data transmitted by the Client or produced on its behalf in the context of the use of the Services.
This DPA applies to any processing of personal data implemented by Nereva on behalf of the Client from the effective date of the main contract and for the entire duration of the contractual relationship.
Article 2 — Definitions
The terms used in this DPA are understood within the meaning of the GDPR and the FADP, and in particular within the meaning of the following definitions.
Personal data : any information relating to an identified or identifiable natural person.
Processing : any operation performed on personal data.
Controller : the person or entity that determines the purposes and means of the processing.
Processor : the person or entity that processes personal data on behalf of the Controller.
Sub-processor : a third party to which the Processor delegates all or part of its processing activities.
Data breach : a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data.
Data subject : a natural person whose personal data is processed.
Article 3 — Qualification of the Parties
For the processing falling under this DPA, the Client acts as Controller and Nereva acts as Processor.
Each Party complies with the obligations incumbent on it under the qualification thus defined. This qualification entails neither mandate, nor representation, nor delegation beyond the terms of this DPA.
Article 4 — Description of the processing
The description of the processing implemented by Nereva on behalf of the Client is specified in Annex 1 of this DPA, which forms an inseparable part of it. Annex 1 indicates in particular the subject matter and nature of the processing, the duration of the processing, the purpose of the processing, the categories of personal data processed, and the categories of data subjects.
Article 5 — Obligations of Nereva as Processor
Nereva undertakes to process personal data only on documented instructions from the Controller, in accordance with Article 28(3) of the GDPR and Article 9 of the FADP.
As such, Nereva undertakes (i) to process personal data only for the purposes defined in Annex 1; (ii) to guarantee the confidentiality of the data processed; (iii) to ensure that persons authorised to process the data are subject to an appropriate contractual or statutory obligation of confidentiality; (iv) to implement appropriate technical and organisational measures under the conditions of Article 9; (v) to comply with the conditions provided for in this DPA for the use of a sub-processor under the conditions of Article 10; (vi) to assist the Controller in fulfilling its own obligations under the conditions of Article 12; (vii) to notify the Controller of any data breach under the conditions provided for in Article 13; (viii) to make available to the Controller the information necessary to demonstrate compliance with the obligations resulting from this DPA and to allow audits, under the conditions provided for in Article 15; (ix) to inform the Controller without delay if Nereva considers that an instruction received constitutes a breach of the GDPR, the FADP or any other legal provision applicable to data protection.
Article 6 — Documented instructions of the Controller
The documented instructions of the Controller include the provisions of this DPA, the T&Cs and the order form, the technical configurations made by the Controller via the platform, as well as the additional written instructions communicated by the Controller to privacy@nereva.com.
Any instruction exceeding the scope of the agreed Services may be subject to reasonable additional invoicing, after written agreement of the Parties.
Article 7 — Obligations of the Controller
The Controller declares and warrants (i) that it has a valid legal basis for each processing operation implemented via the Services; (ii) that it has informed the data subjects of the processing carried out, under the conditions provided for in Articles 13 and 14 of the GDPR and Articles 19 and 20 of the FADP; (iii) that it has obtained, where applicable, the valid consent of the data subjects; (iv) that it is able to respond to requests to exercise rights made by data subjects under the conditions of Article 12; (v) that it enters in the platform only lawfully collected and accurate personal data; (vi) that it complies with the retention periods applicable to the data entered in the platform; (vii) that it has carried out or had carried out any data protection impact assessment that may be required pursuant to Articles 35 of the GDPR and 22 of the FADP, in particular for the processing of data from the Drivers mobile application; (viii) that it has complied, where applicable, with the obligations to inform, consult or co-determine with staff representatives, and that it has incorporated the relevant arrangements into its internal regulations or any equivalent internal document; (ix) that, when it activates the provision of operational information to a third-party principal, it has formalised with the latter the obligations applicable to the processing of the data thus communicated and has informed the data subjects; (x) that it will indemnify Nereva in accordance with Article 25 bis of the T&Cs in the event of a claim against Nereva resulting directly or indirectly from a breach by the Controller of its own obligations.
Article 8 — Confidentiality
Nereva processes personal data with the strictest confidentiality. Nereva's employees authorised to access the data are subject to a contractual obligation of confidentiality, which survives the termination of their duties.
Nereva does not disclose personal data to any third party, except (i) to sub-processors admitted under the conditions of this DPA; (ii) to the competent public authorities on the basis of a legal obligation or an enforceable decision; (iii) with the prior written consent of the Controller.
Article 9 — Security measures
Nereva implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR and Article 8 of the FADP.
These measures include in particular the encryption of data in transit (TLS 1.2 or higher) and at rest, pseudonymisation where applicable, the limitation and control of access according to the principle of least privilege, strengthened authentication of administrative access, the logging of sensitive actions, regular data backups and the documentation of business recovery procedures, the awareness-raising and continuous training of employees, the periodic performance of security tests, and the logical separation of production, pre-production and development environments.
The detailed description of the technical and organisational measures is specified in Annex 2 of this DPA. Nereva's commitments regarding security constitute best-efforts obligations.
Article 10 — Sub-processing
The Controller authorises Nereva to use sub-processors for the provision of the Services, subject to compliance with the following conditions: (i) the list of authorised sub-processors is specified in Annex 3 of this DPA; (ii) Nereva imposes on each sub-processor obligations equivalent to those provided for in this DPA by contract; (iii) Nereva remains fully liable to the Controller for the performance by the sub-processors of their obligations.
Any change to the list of sub-processors will be notified to the Controller with reasonable notice, which may not be less than thirty (30) days, allowing it to raise reasoned objections. In the event of a persistent objection by the Controller, the Parties will endeavour to find an alternative solution; failing this, the Controller may terminate the contract without penalty.
Article 11 — International data transfers
Nereva undertakes not to transfer personal data outside Switzerland or outside the European Economic Area without having obtained the prior authorisation of the Controller, or having implemented the appropriate safeguards provided for by the GDPR and the FADP, in particular the Standard Contractual Clauses adopted by the European Commission or approved by the FDPIC, and having assessed the adequacy of the level of protection offered by the recipient country in accordance with the applicable guidelines and the Schrems II case law.
As at the effective date of this DPA, personal data is hosted exclusively in Switzerland.
Article 12 — Assistance to the Controller
Nereva provides the Controller, as far as possible and taking into account the nature of the processing, with the assistance necessary to respond to requests to exercise rights made by data subjects, to make notifications of data breaches to the supervisory authorities and to data subjects, to carry out, where applicable, data protection impact assessments (DPIA), it being specified that Nereva provides the Controller with a DPIA template specific to the geolocation processing from the Drivers mobile application, to be completed by the Controller, and to consult, where applicable, the competent supervisory authority.
When Nereva is directly approached with a request to exercise rights by a data subject, it forwards the request without delay to the Controller and does not respond to it itself, unless otherwise instructed in writing by the Controller.
Article 13 — Notification of data breaches
Nereva notifies the Controller of any personal data breach of which it becomes aware as soon as possible and at the latest within seventy-two (72) hours of becoming aware of it.
The notification includes, to the extent of the information available, (i) a description of the nature of the breach; (ii) the categories and approximate number of data subjects concerned; (iii) the categories and approximate number of records concerned; (iv) the likely consequences of the breach; (v) the measures taken or proposed to remedy the breach and mitigate its effects; (vi) the contact details of Nereva's point of contact for obtaining further information.
Nereva keeps documentation of data breaches and makes it available to the Controller upon request.
Article 14 — Fate of data at the end of the contract
At the end of the contract, whatever the cause, and for a period of thirty (30) days following the effective date of termination, Nereva provides the Controller, upon written request, with a functionality to export personal data in a structured, commonly used and machine-readable format.
Upon expiry of this period, Nereva proceeds with the deletion or irreversible anonymisation of the personal data, subject to (i) the legal retention obligations incumbent on Nereva; (ii) cases where the data must be retained for the purposes of ongoing judicial or administrative proceedings.
Nereva certifies in writing to the Controller the proper performance of the deletion or anonymisation operations.
Article 15 — Audit
Nereva makes available to the Controller all the information necessary to demonstrate compliance with the obligations resulting from this DPA, and allows audits, including inspections, to be carried out by the Controller or an independent auditor it has appointed.
Audits are organised according to the following terms: (i) reasonable written notice, which may not be less than thirty (30) days except in cases of proven urgency; (ii) reasonable frequency, not exceeding once (1) per calendar year except in the event of a proven security incident; (iii) scope limited to the processing governed by this DPA; (iv) compliance with confidentiality obligations, operational constraints and the security of Nereva's other clients; (v) costs borne by the Controller, except in the event of proven non-compliance.
Nereva may, alternatively, provide the Controller with certifications, independent audit reports (in particular ISO 27001, SOC 2) or documented security questionnaires, which may satisfy the audit obligations of this Article.
Article 16 — Liability
Each Party is liable for breaches of its own obligations under this DPA, the GDPR and the FADP, in accordance with the applicable legal provisions.
The overall liability and the limitation of compensation owed by Nereva under this DPA are governed by the Terms and Conditions of Use. These provisions are without prejudice to the mandatory rules applicable to data protection, in particular the administrative sanctions provided for by the GDPR and the FADP, and without prejudice to Article 100 paragraph 1 of the Swiss Code of Obligations.
Article 17 — Term and termination
This DPA takes effect on the effective date of the main contract and remains in force for the entire duration of the contractual relationship. It survives the termination of the main contract for the obligations which by their nature are intended to continue, in particular the obligations of confidentiality, deletion and assistance.
Termination of this DPA entails termination of the associated Services. The Controller may terminate this DPA in the event of a serious and persistent breach by Nereva of its obligations under this DPA, under the conditions provided for in the T&Cs.
Article 18 — Applicable law and jurisdiction
This document, as well as the contractual relationship it governs, are governed exclusively by Swiss law, to the exclusion of any conflict-of-laws rule and to the exclusion of the United Nations Convention on Contracts for the International Sale of Goods (CISG, Vienna, 1980).
Any dispute relating to the formation, validity, interpretation, performance or termination of this document falls within the exclusive jurisdiction of the ordinary courts of the canton of Vaud, place of the registered office of Nereva SA, subject to a mandatory appeal to the Swiss Federal Supreme Court.
Article 19 — Reference language
The French version of this DPA alone is legally authoritative. Any translation is provided for information purposes only and cannot bind Nereva SA.
Article 20 — Annexes
This DPA includes the following annexes, which form an integral part of it: Annex 1 (Description of the processing), Annex 2 (Technical and organisational security measures), and Annex 3 (List of authorised sub-processors).
The annexes may be updated according to the terms provided for in this DPA.
Annex 1 — Description of the processing
Subject matter and nature of the processing
The processing of personal data takes place in the context of the provision of the Nereva Services for orchestrating, planning, managing and documenting logistics flows. It includes in particular the hosting and storage of the data entered by the Client, the provision of the platform's functionalities, the generation of documents, certificates and indicators, the transmission of operational notifications to Users and designated recipients, as well as the collection and processing of geolocation data from the Drivers mobile application during active missions, for the purposes of on-board heavy-vehicle navigation, execution traceability and operational visibility for the benefit of the Client and, where applicable, the principal designated by the Client.
Duration of the processing
The processing takes place for the duration of the contractual relationship between the Parties, extended by the retention periods provided for in Article 14 of this DPA and in the T&Cs.
Purpose of the processing
The performance of the Services on behalf of the Controller, in accordance with the T&Cs, the order form and the configurations made by the Controller.
Categories of personal data processed
Identification data : surname, first name, position.
Professional contact details : e-mail address, telephone number.
Account data : credentials, password in encrypted form.
Operational data entered by the Client : this data may include, where applicable, identifiers of drivers or operational contacts.
Geolocation data from the Drivers mobile application : GPS positions collected continuously from the Driver's acceptance of a transport mission until the closure of that mission, as well as the associated timestamps. Collection is automatically interrupted at the closure of the mission and does not extend to the Driver's off-duty periods, breaks or personal time. This data is processed for the following exclusive purposes: (i) on-board navigation suited to heavy vehicles, provided via the HERE API; (ii) execution traceability of the mission for the benefit of the Client in its capacity as the Driver's employer; (iii) provision of real-time operational visibility to the principal designated by the Client, under the conditions of precision and duration defined by the configuration subscribed in the order form.
Activity logs and technical usage data : technical information relating to the use of the platform.
No sensitive data within the meaning of Article 9 of the GDPR or Article 5 of the FADP must be entered in the platform, except with the express prior agreement of the Parties.
Categories of data subjects
The data subjects concerned by the processing are Users with access to the Services under a licence, the representatives, directors and points of contact of the Client, the Drivers and operational contacts entered by the Client in the platform, as well as the Client's commercial partners whose contact details are entered in the platform.
Annex 2 — Technical and organisational security measures
Access security
Access security measures include strong authentication of administrative accounts, a robust password policy, access management according to the principle of least privilege, and immediate revocation of access for employees leaving Nereva.
Data security
Data security measures include encryption in transit (TLS 1.2 or higher), encryption at rest of databases and backups, pseudonymisation where applicable, and the logical partitioning of production, pre-production and development environments.
Operational security
Operational security measures include the logging and monitoring of sensitive actions, regular data backups, a documented disaster recovery procedure (DRP), and the performance of periodic security tests.
Organisational security
Organisational security measures include confidentiality clauses enforceable against employees, an awareness-raising and continuous training approach, and a security incident management procedure.
Physical security
The servers and infrastructure hosting personal data benefit from the physical security measures implemented by Amazon Web Services in its data centres located in Switzerland, which are certified according to several recognised standards (ISO 27001 and other equivalent standards).
Annex 3 — List of authorised sub-processors
As at the effective date of this DPA, the authorised sub-processors are as follows.
Amazon Web Services EMEA SARL — 38 avenue John F. Kennedy, L-1855 Luxembourg. Activity: cloud infrastructure hosting. Data location: Switzerland (eu-central-2 “Switzerland (Zurich)” region).
HERE Europe B.V. — Kennedyplein 222-226, 5611 ZT Eindhoven, Netherlands. Activity: provision of mapping, route calculation and on-board navigation APIs suited to heavy vehicles, integrated into the Drivers mobile application. Data transmitted: GPS positions and routing requests linked to active missions. Processing location: European Union. Contractual framework: HERE Data Processing Agreement concluded with Nereva SA and, where applicable, standard contractual clauses for any transfer outside the European Economic Area.
The complete and up-to-date list of sub-processors processing personal data, including where applicable authentication, monitoring, payment and transactional messaging providers, is made available to the Client upon request sent to privacy@nereva.com.
